Shopify access & permissions

setlist asks for the minimum Shopify permissions up front, then requests extra access only when you use a feature that needs it. This page explains those in-app access requests.


Why you'll see access prompts

When you install setlist it asks for exactly two permissions — read_products and write_products — enough to plan and create product cards. Everything else is optional and setlist requests it in context, right where you first need it. Each request opens Shopify's own approval dialog; you can grant it or skip and keep working, then request it again later.

Granting is a quick Shopify approval — not a reinstall — and takes effect immediately.

The four access groups

Access groupShopify permissionsRequested when…Unlocks
Inventory accessread_locations, read_inventory, write_inventoryYou push a product to ShopifySetting SKUs and starting quantities on the new Shopify product. The Push to Shopify button stays disabled until this is granted.
Publishing accessread_publications, write_publicationsYou list a product livePublishing the product to your selected sales channels.
Commerce accessread_customers, write_customers, write_draft_ordersYou create a user-testing draft order (or link a tester to a Shopify customer)Linking testers to Shopify customers and creating sample-sale draft orders.
Order accessread_ordersBefore your first Shopify sales sync, from the card on the Forecasts pageReading the most recent 60 days of Shopify orders and aggregating monthly per-SKU sales history. Older months come from workbook imports.

Each appears as a warning banner headed with the group's name — e.g. "Inventory access needed" with a Request inventory access button — at the exact spot the action lives (the launch checklist and Status panel, the user-test form and test detail, or the top of the Forecasts page). An action may already be visible but disabled. Once access is granted, the banner disappears and the action becomes available.

If you skip a request

Nothing breaks — you just can't take that one Shopify action until you grant it. setlist leaves the request banner in place ("Access was declined. You can keep working without this Shopify action, or request it again whenever you are ready."), and the underlying action stays blocked with a message naming the group and the exact permissions still missing.

If the access request itself fails because your store hasn't picked up setlist's latest permission list, you'll see "This access isn't enabled on your store yet. Please refresh and try again, or contact Setlist support if it keeps happening." — that one is on setlist's side, not yours.

What setlist deliberately doesn't ask for

setlist never requests staff-account access (read_users), a Shopify protected-data scope. The consequence is visible in one place: Settings → Team can't offer a picker of your real Shopify staff, so you type teammates' names in by hand.

See also